CVE-2013-1887: XSS
Published Mar 27, 2013
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in the Views module 7.x-3.x before 7.x-3.6 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via certain view configuration fields.
Affected Software
14 affected components
Views Project Views=7.x-3.0
Views Project Views=7.x-3.0-alpha1
Views Project Views=7.x-3.0-beta1
Views Project Views=7.x-3.0-beta2
Views Project Views=7.x-3.0-beta3
Views Project Views=7.x-3.0-rc1
Views Project Views=7.x-3.0-rc3
Views Project Views=7.x-3.1
Views Project Views=7.x-3.2
Views Project Views=7.x-3.3
Views Project Views=7.x-3.4
Views Project Views=7.x-3.5
Views Project Views=7.x-3.x-dev
Drupal Drupal
Remediation
Patch Available
Patch Available
Event History
Mar 27, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1887?
CVE-2013-1887 has a moderate severity rating due to its ability to allow cross-site scripting attacks.
2
How do I fix CVE-2013-1887?
To fix CVE-2013-1887, upgrade the Views module to version 7.x-3.6 or later.
3
Who is affected by CVE-2013-1887?
CVE-2013-1887 affects remote authenticated users with certain permissions using the vulnerable versions of the Views module.
4
What types of attacks can be executed due to CVE-2013-1887?
CVE-2013-1887 allows attackers to inject arbitrary web scripts or HTML into certain view configuration fields.
5
What versions of the Views module are vulnerable to CVE-2013-1887?
The vulnerable versions of the Views module are 7.x-3.0 through 7.x-3.5.